The Department of War suspended CMMC Phase 2 on July 13, 2026. Your DFARS 252.204-7012 obligations did not move.
This page tracks what changed, what did not, and what happens between now and the Reform Task Force’s report. It will be updated as that report lands, not rewritten from scratch.
Not sure what this means for your contract?
A scope review tells you whether your Microsoft environment holds up under NIST 800-171, independent of what the Task Force decides in September.
Jul 13
Suspension date
60 Days
Task Force review window
~200
GCC Hight tenants managed
7012
DFARS Clause, Unchanged
Four things did not move on July 13, and each one carries its own enforcement mechanism independent of CMMC’s certification schedule.
Still Applies
Suspended
Not automatically. Contracting officers were directed to remove Level 2 (C3PAO) and Level 3 requirements from active solicitations and existing contracts, but only through formal modification, at the next option period or scheduled administrative action. Until that modification reaches your specific contract, the language already in it controls.
Four sources are telling contractors four different things right now. DoW sets the certification timeline, and that’s what moved. DFARS and the False Claims Act set the exposure, and that predates CMMC entirely. Primes set their own flow-down expectations on their own schedule. Public commentary sets the noise floor, and it’s the loudest of the four, not the most accurate.
A suspended government mandate doesn’t suspend a prime’s own bar for its supply chain.
The CMMC Reform Task Force must deliver its report within 60 days of July 13, 2026, which lands around mid-September.
Agile IT currently manages close to 200 GCC High tenants. That scale is the reason to ask before assuming a specific tenant’s configuration holds up under NIST 800-171, rather than after an assessor finds the gap.
Whether your GCC High or Azure Government environment actually meets NIST 800-171 is a separate question from what the Task Force decides in September. Which one are you certain of right now?
Yes. Phase 1 self-assessment requirements have been in force since November 10, 2025, and remain firmly in place.
What is suspended is Phase 2: the requirement for independent third-party (C3PAO) certification, which was scheduled to take effect November 10, 2026.
The transition to CMMC Phase 2, along with all pending and future CMMC implementation milestones across Department of War solicitations and contracts. That includes Phases 3 and 4.
Phase 1 self-assessment, DFARS 252.204-7012, NIST SP 800-171 Rev 2 compliance, and SPRS score postings and annual affirmations continue without interruption.
No. The Department of War’s own release states plainly that the action does not eliminate the requirement to protect federal data.
Contractors remain contractually obligated to safeguard covered defense information under DFARS 252.204-7012, regardless of what happens to the certification schedule.
A task force established by the DoW Chief Information Officer to review the certification program and recommend changes aligned to the Department’s Acquisition Transformation System.
The task force is required to deliver a final report to the CIO within 60 days of July 13, 2026, putting a report on the CIO’s desk around mid-September.
The Department opened a Request for Information seeking industry input on compliance costs and program structure. Responses were due by 12:00 p.m. ET on August 14, 2026.
That window has closed. The task force is now synthesizing what it received.
Not automatically. Contracting officers have been directed to remove Level 2 and Level 3 requirements from active solicitations and existing contracts, but only through formal modification, at the next option period or scheduled administrative action.
Until that modification lands on your specific contract, the existing language controls. A memo does not rewrite a contract by itself.
Keep current NIST SP 800-171 self-assessments and SPRS postings on schedule. Nothing about them paused.
Check your active contracts and solicitations for Level 2 or Level 3 language rather than assuming it disappeared, and watch for the task force’s report in September.
You come in with what you know about your environment. We bring the experience to make sense of it.
If compliance shapes your organization, it should shape your IT. The boundary is a decision you can still make on your own terms, or one an assessment date makes for you. Which of those are you working on this quarter?